Техническая информация
- [HKCU\Software\Classes\ms-settings\Shell\Open\command] '' = '<Полный путь к файлу>'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'yГ¶netimpanel' = '"%TEMP%\_rt_958234.exe"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\svchost.exe
- <SYSTEM32>\tasks\yГ¶netimpanel
- %TEMP%\_rt_958234.exe
- %TEMP%\_rt_963781.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\_rt_963781.exe.log
- %APPDATA%\subdir\client.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\_rt_958234.exe.log
- %APPDATA%\logs\03-01-2026
- %APPDATA%\subdir\client.exe
- '46.##.77.130':1604
- DNS ASK ip##pi.com
- DNS ASK fr###eoip.net
- DNS ASK ap#.#pify.org
- '%TEMP%\_rt_958234.exe'
- '%TEMP%\_rt_963781.exe'
- '%APPDATA%\subdir\client.exe'
- '<SYSTEM32>\fodhelper.exe' (со скрытым окном)
- '%WINDIR%\immersivecontrolpanel\systemsettings.exe' -ServerName:microsoft.windows.immersivecontrolpanel
- '<SYSTEM32>\svchost.exe' -k appmodel -p -s camsvc
- '<SYSTEM32>\systemsettingsadminflows.exe' OptionalFeaturesAdminHelper (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "yжnetimpanel" /sc ONLOGON /tr "%TEMP%\_rt_958234.exe" /rl HIGHEST /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "yжnetimpanel" /sc ONLOGON /tr "%APPDATA%\SubDir\Client.exe" /rl HIGHEST /f